Trojan

Trojan.Win32.Vobfus.toz removal tips

Malware Removal

The Trojan.Win32.Vobfus.toz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Vobfus.toz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Trojan.Win32.Vobfus.toz?


File Info:

name: 11F8D755329D695BE672.mlw
path: /opt/CAPEv2/storage/binaries/a6c2ac76b4b4467b2ea44ece81d26ccb2e10dd7fcccf9fd7c4169942c6f2f9fa
crc32: 085FF092
md5: 11f8d755329d695be6728e28faa72be5
sha1: 8fc2a54c95fad2ec1ca8a6b04436cb45ba0b6480
sha256: a6c2ac76b4b4467b2ea44ece81d26ccb2e10dd7fcccf9fd7c4169942c6f2f9fa
sha512: 6a1f449b76ff73f52d41ed1c3433cf8eabb4d44885fc7227e1757f5d3e5729e7e9431c75a556b4d819a952e835509691f169c410d9ffa817d7b19cad29393a5f
ssdeep: 6144:TT7fvTlIpr1f+XqO5aOmSGFDbeOjLPmU:TnTlIB1f+55SpNPmU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C74F57AFB724884D668193017E2C7D205923EF9CAA341436E6437E958BAF4F1C18F97
sha3_384: b002ee52e74e9be7690757a9408132923d1ba158937612647553120113b41cebf0fd3252ec6e17a205c5daa2bf6f4d33
ep_bytes: 682c124000e8eeffffff000000000000
timestamp: 2008-09-27 05:14:06

Version Info:

0: [No Data]

Trojan.Win32.Vobfus.toz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKDZ.79611
ClamAVWin.Trojan.Vobfus-64
FireEyeGeneric.mg.11f8d755329d695b
CAT-QuickHealTrojan.Beebone.D
McAfeeW32/Autorun.worm.aaeh
MalwarebytesGeneric.Worm.AutoRun.DDS
VIPRETrojan.GenericKDZ.79611
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 003c363a1 )
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.5329d6
BaiduWin32.Worm.VB.av
VirITTrojan.Win32.Zyx.KH
CyrenW32/Vobfus.O.gen!Eldorado
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32Win32/AutoRun.VB.AVQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Vobfus.toz
BitDefenderTrojan.GenericKDZ.79611
NANO-AntivirusTrojan.Win32.Jorik.cinayd
AvastWin32:VB-ACSQ [Trj]
TencentTrojan.Win32.Vobfus.ha
TACHYONTrojan/W32.VB-Jorik.356352.B
SophosW32/SillyFDC-IE
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebWin32.HLLW.Autoruner1.15668
TrendMicroTROJ_AGENT_010446.TOMB
McAfee-GW-EditionBehavesLike.Win32.VBObfus.fm
Trapminemalicious.moderate.ml.score
EmsisoftTrojan.GenericKDZ.79611 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.79611
JiangminTrojan/Vbobf.b
AviraTR/Patched.Ren.Gen
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Generic.D136FB
ZoneAlarmTrojan.Win32.Vobfus.toz
MicrosoftVirTool:Win32/VBInject.WX
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R27035
BitDefenderThetaAI:Packer.F1349C781D
ALYacTrojan.GenericKDZ.79611
MAXmalware (ai score=86)
VBA32Trojan.Vobfus
Cylanceunsafe
PandaW32/Vobfus.GEW.worm
TrendMicro-HouseCallTROJ_AGENT_010446.TOMB
RisingWorm.Pronny!1.E3E1 (CLASSIC)
IkarusVirus.Win32.VBInject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Jorik.EGLG!tr
AVGWin32:VB-ACSQ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Win32.Vobfus.toz?

Trojan.Win32.Vobfus.toz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment